drjobs Senior Security Compliance Consultant

Senior Security Compliance Consultant

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

Clearwater - USA

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

Own The Role:

SP6 (C3PAO Authorized Organization) is looking for a Compliance SME wanting to take the next step in their career! In this role you will assist organizations in solidifying and strengthening their security posture while also conducting assessments for those pursuing certification.

Joining our Compliance team you will see your impact across the company as you take ownership over customer projects and advising our platform team on the different compliance rules.

From there you will be supporting Defense Industrial Base (DiB) companies to ensure they are CMMC and/or NIST 800171 compliant. You will accomplish this through providing preaudit readiness and GAP assessments plans of action and milestones (POA&M) support Compliance as a Service (CaaS) and official C3PAO assessments.

How Youll Drive Success:

Advisory Services
  • Leading cybersecurity gap assessments aligned with NIST SP 800171 and Cybersecurity Maturity Model Certification (CMMC).
  • Supporting the daytoday activities of engagements for external clients as a contributing member of SP6s customerfacing Cyber Risk & Compliance practice.
  • Assist external customers in their FedRAMP DFARS 7012 CMMC and NIST 800171 compliance initiatives.
  • Applying cyber compliance / risk management knowledge control principles and technical knowledge across cyber risk and compliance engagements.
  • Consulting with end clients to gather requirements and understand our clients key business and security challenges. Working with team members to advise on practical and costeffective solutions to help mitigate our clients cybersecurity risks and challenges.
  • In depth knowledge of relevant security regulatory compliance requirements and translating those into business processes and security controls to enhance and support clients compliance and audit capabilities.
  • Articulating and defending IT controls testing approach and performing test of design and operating effectiveness.
  • Develop and deliver training to internal teams and customers.
  • Establishing and maintaining effective working relationships with colleagues existing clients and prospective client organizations.
  • Supporting the ASCERA product team and advising them on SP6S NIST continuous monitoring software.
C3PAO Assessments
  • Conducting formal assessments of organizations cybersecurity practices using the CMMC assessment process (CAP).
  • Collaborate with client organizations to plan assessments develop assessment schedules and ensure readiness
  • Assess the effectiveness of security practices and ensure they align with the CMMC practices and processes.
  • Interview key personnel within the organization to understand how cybersecurity practices are implemented and maintained.
  • Evaluate sufficiency and adequacy of evidence to verify implementation.
  • Maintain an objective and unbiased stance during the assessment process ensuring that conclusions are based on facts and evidence.
  • Ensure that all documentation is properly prepared for submission to eMASS if the organization is seeking certification.

To Be Successful:
  • 58 years of experience testing and documenting IT security controls including experience managing and facilitating external IT audits.
  • 5 years of experience leading external or internal audits e.g. CMMC FedRAMP ISO 27001 PCI.
  • 3 years of experience building security programs in alignment with NIST CSF NIST 80053 and/or NIST 800171.
  • 3 years of experience with Cloud Security.
  • CMMC Certified Assessor (CCA) or Certified Professional (CCP).
  • CISSP CISM CISA CRISC or other related certification.
  • Selfdriven with a strong desire to succeed.
  • Ability to engage with customers/executives and foster positive relationships.
  • Exceptional communicator and ability to relay complex technical concepts to nontechnical audience.

Why SP6
  • Recognized as one of North Americas top professional service partners.
  • The chance to be part of a winning team and a premier Splunk partner.
  • Competitive salary and OTE.
  • 100 employerpaid health insurance (Goldrated plan).
  • 401(k) with company match.
  • 30 days of annual paid time off 4 weeks Paid Time Off Holidays)
  • Significant Training and Development and Certification attainment.
  • Opportunity for longterm career advancement.
  • Your contributions are felt and recognized by our growing company.
  • Grown over 100 in the last 2 years.

About SP6:
SP6 is an industry recognized C3PAO (Certified ThirdParty Assessor Organization) dedicated to assisting organizations in effectively identifying and managing cyber risks while ensuring compliance with industry standards federal laws and regulations.

SP6 has developed ASCERA a powerful automation tool bringing security and compliance teams closer together by providing realtime testing of security controls to determine effectiveness and gather system generated evidence.


#LIREMOTE


Required Experience:

Senior IC

Employment Type

Full-Time

Company Industry

About Company

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.